Network access method, network access device, medium and electronic device for a communication network

By pre-store the correspondence between the access point and the domain name, IMSI and the user name in VPDN AAA, and automatically bind to generate authentication information, it solves the problem that 5G terminals cannot access multiple domain names without configuration, improves network access efficiency and security, reduces user complaints, and is applicable to 5G SA and 4G LTE networks.

CN115086956BActive Publication Date: 2025-08-01CHINA TELECOM CORP LTD
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202110267514.3
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2021-03-11
Publication Date
2025-08-01
Estimated Expiration
2041-03-11

AI Technical Summary

Technical Problem

In the 5G era, terminal devices cannot carry username and password information, resulting in 5G users being unable to implement single account multi-domain authentication through customized services, which affects user business experience. The existing SMF locally configures public username and password problems poses security risks and low flexibility.

Method used

By pre-stored the correspondence between access point information and domain names in VPDN AAA, and the correspondence between international mobile user identification code information and user names, the domain name and user name are automatically bound to generate authentication information, so that the terminal is configured without configuration, and secondary authentication is performed on the Layer 2 tunnel protocol network server, which is suitable for 5G SA and 4G LTE networks.

Benefits of technology

It improves the efficiency and security of terminal network access, reduces the configuration error rate, reduces the traffic volume of user complaints, realizes the function of multiple domain names for a single account, and enhances the stability of the network and user perception.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115086956B_ABST
    Figure CN115086956B_ABST
Patent Text Reader

Abstract

The present disclosure provides a method for accessing a communication network, a device for accessing a communication network, a medium, and an electronic device, which relate to the technical field of communication networks. Among them, the method for accessing a communication network includes receiving an authentication request sent by a session management function terminal; parsing the access point information and the international mobile subscriber identity information included in the authentication request; determining a corresponding domain name according to the access point information and a first correspondence between the pre-stored access point information and the domain name; determining corresponding user name information according to the international mobile subscriber identity information; binding the domain name and the user name information and generating authentication information; and sending the authentication information to the session management function terminal. Through the technical solution provided by the present disclosure, the configuration-free authentication of a single account with multiple domain names is realized, and the user's network access experience and network access security are improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates to the technical field of communication networks, and in particular, to a method for accessing a communication network, a device for accessing a communication network, a computer-readable storage medium, and an electronic device. Background Art

[0002] Currently, with the advent of the 5G (5th Generation Mobile Networks or 5th Generation Wireless Systems, 5th-Generation, the fifth-generation mobile communication technology, hereinafter referred to as 5G or 5G technology) era, communication networks have encountered information security challenges in different application scenarios. Therefore, information security has become one of the security indicators in the 5G era.

[0003] In the related art, a terminal device can establish a virtual private network through VPDN (Virtual Private Dial Network) to transmit information with high security requirements.

[0004] However, for a VPDN to access the internal network, after setting the access point information on the terminal, it is also necessary to set an account and a domain name to form a username to access the network. However, there are many types of 5G terminals, and some terminals cannot report the username and password information to the core network element. Moreover, some Internet of Things terminals do not support the free configuration of usernames and passwords, resulting in 5G users being unable to achieve single-account multi-domain configuration-free authentication through customized services, which affects the user service experience.

[0005] It should be noted that the information disclosed in the above background art section is only used to enhance the understanding of the background of the present disclosure, and thus may include information that does not constitute the prior art known to those of ordinary skill in the art. Summary of the Invention

[0006] The purpose of the present disclosure is to provide a method for accessing a communication network, a device for accessing a communication network, a medium, and an electronic device, which at least overcome to some extent the problem of low efficiency in configuring access network information in the related art.

[0007] Other features and advantages of the present disclosure will become apparent through the following detailed description, or will be learned in part through the practice of the present disclosure.

[0008] According to one aspect of the present disclosure, a method for accessing a communication network is provided, including: receiving an authentication request sent by a session management function terminal; parsing the access point information and international mobile subscriber identification code information included in the authentication request; determining a corresponding domain name according to the access point information and a first correspondence between the pre-stored access point information and the domain name; determining corresponding user name information according to the international mobile subscriber identification code information; binding the domain name and the user name information and generating authentication information; and sending the authentication information to the session management function terminal.

[0009] In an embodiment of the present disclosure, the method for accessing a communication network further includes: pre-storing a first correspondence between the access point information and the domain name; and pre-storing a second correspondence between the international mobile subscriber identification code information and the user name information.

[0010] In an embodiment of the present disclosure, determining a corresponding domain name according to the access point information and the first correspondence between the pre-stored access point information and the domain name includes: determining whether the access point information matches the pre-stored access point information; if it is determined that the access point information matches the pre-stored access point information, determining the domain name according to the access point information and the first correspondence.

[0011] In an embodiment of the present disclosure, determining corresponding user name information according to the international mobile subscriber identification code information includes: determining whether the international mobile subscriber identification code information matches the pre-stored international mobile subscriber identification code information; if it is determined that the international mobile subscriber identification code information matches the pre-stored international mobile subscriber identification code information, determining the user name information according to the international mobile subscriber identification code information and the second correspondence.

[0012] In an embodiment of the present disclosure, the method for accessing a communication network further includes: if it is determined that the access point information does not match the pre-stored access point information, or it is determined that the international mobile subscriber identification code information does not match the pre-stored international mobile subscriber identification code information, feeding back authentication failure information to the session management function terminal for the session management function terminal to generate an authentication request according to the public user name information configured locally.

[0013] According to one aspect of the present disclosure, another method for accessing a communication network is provided. The method for accessing a communication network includes: sending an authentication request to an access network authentication device, where the access network authentication device can generate authentication information through the above-mentioned method for accessing a communication network; receiving the authentication information fed back by the access network authentication device, where the authentication information includes user name information, a domain name, and tunnel address information; and sending the authentication information to a user port function terminal for the user port function terminal to request a layer 2 tunneling protocol network server for secondary authentication according to the tunnel address information.

[0014] According to one aspect of the present disclosure, another method for accessing a communication network is provided. The method for accessing a communication network includes: receiving authentication information sent by a session management function terminal, where the authentication information is generated by the above method for accessing a communication network by an access network authentication device, and the authentication information includes tunnel address information; and requesting a Layer 2 Tunneling Protocol (L2TP) network server to perform secondary authentication according to the tunnel address information.

[0015] In an embodiment of the present disclosure, the method for accessing a communication network further includes: requesting a Layer 2 Tunneling Protocol (L2TP) network server to perform secondary authentication according to the tunnel address information includes: determining a corresponding Layer 2 Tunneling Protocol (L2TP) network server according to the tunnel address information; sending a tunnel address information request to the Layer 2 Tunneling Protocol (L2TP) network server for the Layer 2 Tunneling Protocol (L2TP) network server to perform secondary authentication; receiving confirmation information for establishing a tunnel from the Layer 2 Tunneling Protocol (L2TP) network server, where the confirmation information includes an IP address access domain name; and sending the IP address access domain name to the terminal for the terminal to access the network according to the IP address access domain name.

[0016] According to another aspect of the present disclosure, an apparatus for accessing a communication network is provided. The apparatus for accessing a communication network includes: a receiving module, configured to receive an authentication request sent by a session management function terminal; a parsing module, configured to parse access point information and International Mobile Subscriber Identity (IMSI) information included in the authentication request; a determining module, configured to determine a corresponding domain name according to the access point information and a first correspondence between pre-stored access point information and domain names; the determining module is further configured to determine corresponding user name information according to the International Mobile Subscriber Identity (IMSI) information; a binding module, configured to bind the domain name and the user name information and generate authentication information; and a sending module, configured to send the authentication information to the session management function terminal.

[0017] According to still another aspect of the present disclosure, an electronic device is provided, including: a processor; and a memory, configured to store executable instructions of the processor; wherein the processor is configured to execute the above method for accessing a communication network by executing the executable instructions.

[0018] According to yet another aspect of the present disclosure, a computer-readable storage medium is provided, on which a computer program is stored, and when the computer program is executed by a processor, the above method for accessing a communication network is implemented.

[0019] An embodiment of the present disclosure provides a solution for accessing a communication network, including:

[0020] 1. Currently, some terminals cannot carry user name and password information. When such terminals that cannot carry user name and password information use SMF (Session Management Function) to locally configure a common user name and password, there is a problem of relatively high security risks. The present disclosure solves such a problem.

[0021] 2. The existing configuration-free policy for the common username and password of the SMF local configuration uniformly uses the username and password and cannot be targeted at a specific terminal. The present disclosure realizes flexible control of user terminals and also realizes the management and control of different users, improving the perception of enterprise users.

[0022] 3. By setting up an online information library that binds access point information to domain names, the present disclosure not only realizes the function of a single account accessing multiple domain names but also realizes the function that the terminal does not need to configure username information regardless of which domain name service it accesses, reducing the business unavailability and obstacle complaints caused by incorrect configuration due to the switching of the terminal's username information, and effectively reducing the call volume of the same type of customer service complaints.

[0023] 4. The present disclosure can not only be applied to the single-account multi-domain access of wireless VPDN users and terminal password-free configuration in a 5G SA (Stand Alone) network but also be applied to networks such as 4G LTE (the 4th Generation Mobile Communication Technology Long Term Evolution) with AAA (Authentication Authorization Accounting) deployed.

[0024] 5. The present disclosure does not need to add network elements in the 5G SA network, fully considers the compatibility with the existing network, realizes a simple database function transformation of the AAA device, and further improves the authentication process.

[0025] It should be understood that the above general description and the following detailed description are only exemplary and explanatory and cannot limit the present disclosure. BRIEF DESCRIPTION OF THE DRAWINGS

[0026] The accompanying drawings herein are incorporated into the specification and constitute a part of the specification, showing embodiments consistent with the present disclosure and, together with the specification, are used to explain the principles of the present disclosure. Obviously, the accompanying drawings in the following description are only some embodiments of the present disclosure, and those of ordinary skill in the art can obtain other drawings without creative efforts based on these drawings.

[0027] Figure 1 A flowchart showing a method for a communication network to access the network in an embodiment of the present disclosure;

[0028] Figure 2 A flowchart showing another method for a communication network to access the network in an embodiment of the present disclosure;

[0029] Figure 3 Flowchart showing another method for a communication network to access the network in an embodiment of the present disclosure;

[0030] Figure 4 Flowchart showing yet another method for a communication network to access the network in an embodiment of the present disclosure;

[0031] Figure 5 Flowchart showing still another method for a communication network to access the network in an embodiment of the present disclosure;

[0032] Figure 6 Flowchart showing still another method for a communication network to access the network in an embodiment of the present disclosure;

[0033] Figure 7 Flowchart showing still another method for a communication network to access the network in an embodiment of the present disclosure;

[0034] Figure 8 Flowchart showing still another method for a communication network to access the network in an embodiment of the present disclosure;

[0035] Figure 9 Flowchart showing still another method for a communication network to access the network in an embodiment of the present disclosure;

[0036] Figure 10 Flowchart showing still another method for a communication network to access the network in an embodiment of the present disclosure;

[0037] Figure 11 Flowchart showing still another method for a communication network to access the network in an embodiment of the present disclosure;

[0038] Figure 12 Schematic diagram of an access device for a communication network in an embodiment of the present disclosure;

[0039] Figure 13 Block diagram of the structure of an electronic device in an embodiment of the present disclosure. Detailed implementation manners

[0040] Example embodiments will now be described more fully with reference to the accompanying drawings. However, the example embodiments can be implemented in various forms and should not be construed as limited to the examples set forth herein; rather, these embodiments are provided so that this disclosure will be more complete and comprehensive, and will fully convey the concept of the example embodiments to those skilled in the art. The described features, structures, or characteristics can be combined in any suitable manner in one or more embodiments.

[0041] In addition, the accompanying drawings are only schematic illustrations of the present disclosure and are not necessarily drawn to scale. The same reference numerals in the drawings denote the same or similar parts, and thus repeated descriptions thereof will be omitted. Some of the block diagrams shown in the drawings are functional entities and do not necessarily correspond to physically or logically independent entities. These functional entities may be implemented in software form, or in one or more hardware modules or integrated circuits, or in different networks and / or processor devices and / or microcontroller devices.

[0042] Figure 1 is a flowchart of a method for a communication network to access the network provided by an exemplary embodiment of the present application. As Figure 1 shown, the present disclosure uses a communication network based on the SA (Stand Alone) architecture to implement the method for a communication network to access the network. Among them, in the communication network, there are UE (User Equipment), AMF (Access and Mobility Management Function), UDM (Unified Data Management), SMF (Session Management Function), VPDN AAA (Virtual Private Dial Network Authentication Authorization Accounting), UPF (User Port Function), and LNS (Layer 2 Tunneling Protocol Network Server).

[0043] (1) AAA is a security management mechanism for access control in network security, providing three security services: authentication, authorization, and accounting. For example, AAA is a server program capable of processing user access requests, used to provide authentication, authorization, and account services, manage the network server accessed by users, and provide services to users with access rights. In addition, AAA is used for centralized management of user information and usually works in coordination with network access control, gateway servers, databases, and user information directories. For example, the Remote Authentication Dial-In User Service is used as the network connection server interface of the AAA server.

[0044] (2) The UE may be a mobile terminal such as a mobile phone, a game console, a tablet computer, an e-book reader, smart glasses, an MP4 (Moving Picture Experts Group Audio Layer IV) player, a smart home device, an AR (Augmented Reality) device, a VR (Virtual Reality) device, etc. Alternatively, the UE may also be a personal computer (PC), such as a laptop computer and a desktop computer, etc.

[0045] For example, the clients of the application programs installed in different UEs may be the same, or the clients of the application programs installed on two UEs are the clients of the same type of application programs on different control system platforms. Based on the differences in the terminal platforms, the specific forms of the application program clients may also be different. For example, the application program client may be a mobile phone client, a PC client, or a World Wide Web (WWW) client, etc.

[0046] For example, the number of the above-mentioned UEs may be more or less. For example, the above-mentioned UE may be only one, or the above-mentioned UEs may be dozens or hundreds, or a larger number. The embodiments of the present application do not limit the number and device types of the UEs.

[0047] For example, the UE is connected to the AMF, the AMF is connected to the UDM, the UDM is connected to the SMF, the SMF is connected to the VPDN AAA, the VPDN AAA is connected to the UPF, and the UPF is connected to the LNS through a communication network, but not limited thereto.

[0048] For example, the communication network is a wired network or a wireless network, etc., but not limited thereto.

[0049] For example, the AMF includes a mobility management function for the UE. For example, the registration management, connection management, reachability management, mobility management, access authentication management, and access authorization management of the UE, etc., and not limited thereto.

[0050] In one embodiment, the UDM includes a unified data management function for the AMF and the SMF. For example, the generation of authentication credentials, support for unhiding privacy-protected user identifiers, access authentication based on subscription data (such as roaming restrictions), registration management of UE services (for example, AMF management for storing services for the UE, SMF management for storing services for the UE session), support for service or session continuity and lawful interception functions by maintaining ongoing sessions of the SMF, etc., and not limited thereto.

[0051] In one embodiment, the SMF includes session management functions for the UE and the AMF, and can, for example, select a UPF based on the UE or session granularity, collect charging data, connect to a charging center, etc., and is not limited thereto.

[0052] In one embodiment, the UPF includes user port functions, which include: A / D (Analog to Digital Converter) conversion, signaling conversion, termination of the UNI (User Networks interface) function, activation or deactivation of the UNI, processing of the UNI payload path or bearer capacity, testing of the UNI, maintenance, management, control functions, etc., and is not limited thereto.

[0053] In one embodiment, the LNS includes an L2TP (Layer 2 Tunneling Protocol) protocol server device, which represents the logical termination of a PPP (Point to Point Protocol) session for tunneling.

[0054] In one embodiment, the above-mentioned wireless network or wired network uses standard communication technologies and / or protocols. The network is usually the Internet, but can also be any network, including but not limited to any combination of a local area network (LAN), a metropolitan area network (MAN), a wide area network (WAN), a mobile, wired or wireless network, a private network or a virtual private network). In some embodiments, technologies and / or formats including Hyper Text Mark-up Language (HTML), Extensible Markup Language (XML), etc. are used to represent data exchanged through the network. In addition, conventional encryption technologies such as Secure Socket Layer (SSL), Transport Layer Security (TLS), Virtual Private Network (VPN), Internet Protocol Security (IPsec), etc. can be used to encrypt all or some of the links. In other embodiments, customized and / or proprietary data communication technologies can also be used to replace or supplement the above data communication technologies.

[0055] Figure 1 The shown method for a communication network to access the network includes:

[0056] In step S102, an access request is sent: The UE can send an access request to the AMF. The access request includes APN (Access Point Name) information and IMSI (International Mobile Subscriber Identification Number) information.

[0057] Among them, the APN can also be replaced by DNN (Data Network Name) information.

[0058] In one embodiment, as a network access technology, the APN is a parameter that must be configured when a mobile phone accesses the Internet. It determines the access method by which the mobile phone accesses the network. The APN is the unique identifier of the target network. For example, the UE can be connected to the customer intranet identified by a dedicated APN, and the access channel can be isolated from the public network, thereby ensuring the security of network access and the privacy of data transmission. For mobile phone users, different external network types can be accessed, such as, for example, the Internet, WAP (Wireless Application Protocol), websites, enterprise internal networks within a group, and industry-specific private networks, etc., but not limited thereto.

[0059] In one embodiment, the APN information includes an APN network identifier and an APN operator identifier. Among them, the APN network identifier is the identifier through which the user can connect to an external network via a GGSN (Gateway GPRS Support Node) or a PGW (PDN Gateway). The APN network identifier is assigned by the network operator to an ISP (Internet Service Provider) or an intranet and is consistent with the fixed Internet domain name of the APN. It is an essential component of the APN.

[0060] In addition, the APN operator identifier is used to identify the network to which the GGSN or PGW belongs and is an optional component of the APN.

[0061] In one embodiment, the description, definition, and use of the APN are equally applicable to 5G DNN. 5G DNN supports the independent deployment and selection of some network elements (NEs) of the CN (Core Network), and also provides user-level QoS (Quality of Service) control. However, it is not end-to-end and can be considered as a "slicing" technology from part of the core network to a private network.

[0062] In one embodiment, the IMSI is a flag that differentiates mobile users and is stored in the SIM (Subscriber Identity Module) card, which can be used as valid information to distinguish mobile users.

[0063] In step S104, an authentication request is sent: After the AMF receives the access request sent by the UE, it can send an authentication request to the UDM so that the UDM authenticates the APN information in the access request.

[0064] In step S106, authentication information is returned: The UDM determines whether the APN information passes authentication. The UDM checks the APN information against the stored subscription information. After confirming that the APN information passes the check, the authentication is completed, and the UDM returns the authenticated APN information to the AMF.

[0065] In step S108, a connection request is sent: The AMF sends a data connection request to the SMF, and the data connection request includes IMSI information and the authenticated APN information.

[0066] In step S110, default information is supplemented: The SMF checks the IMSI information and the APN information. When it finds that information is missing, it supplements the missing information to ensure the integrity of the information.

[0067] In one embodiment, when the terminal cannot carry username information and domain name information, and the SMF determines that there is no username information corresponding to the IMSI information and / or domain name information corresponding to the APN information in the data connection request, it supplements the missing information with the common username and password configured locally in the SMF.

[0068] In step S112, a verification request is sent: The SMF sends an authentication request to the VPDN AAA, and the authentication request includes the APN information and the IMSI information.

[0069] In step S114, verification information is returned: The VPDN AAA authenticates the APN information and the IMSI information in the authentication request. After completing the authentication of the APN information and the IMSI information, it returns the authentication information to the SMF, and the authentication information includes the APN information, the IMSI information, the tunnel address information, and the tunnel password information.

[0070] In step S116, a tunnel connection request is sent: After the SMF receives the authentication message, it sends a tunnel connection request to the UPF and transparently transmits the authentication information to the UPF.

[0071] Among them, pass-through transmission is transparent transmission, which means that in communication, regardless of the service data being transmitted, it only responsible for transmitting the transmitted data from the source address to the destination address without making any changes to the service data.

[0072] In step S118, send a tunnel establishment request: After receiving the tunnel connection request sent by the SMF, the UPF sends a tunnel establishment request to the LNS according to the tunnel connection request.

[0073] In step S120, return a tunnel establishment confirmation request: After receiving the tunnel establishment request, the LNS returns a tunnel establishment confirmation request to the UE. The tunnel establishment confirmation request includes the destination IP address information assigned to the UE.

[0074] In step S122, access the network: The UE accesses the network using the destination IP address.

[0075] In one embodiment, the user initiates an access request by setting DNN information or APN information on the terminal. The UDM receives the access point DNN information or APN information brought up by the terminal and checks it against the saved subscription information. After confirming that the information check passes, the UDM returns the confirmation information to the AMF.

[0076] In the embodiments of the present disclosure, the AMF sends a data connection request to the SMF. If the terminal cannot carry information such as the username and domain name, it is supplemented with the public username and password information configured locally by the SMF, and an authentication request is sent to the VPDN AAA. The request also carries the access point DNN information or APN information requested by the terminal and the user IMSI information.

[0077] In the embodiments of the present disclosure, after the VPDN AAA verifies the information brought up, it returns an authentication confirmation packet to the SMF. The authentication confirmation packet includes the username and password information, as well as the LNS tunnel address and tunnel password information. After receiving the information, the SMF sends a connection request to the UPF and transparently transmits the information in the authentication confirmation packet to the UPF.

[0078] In the embodiments of the present disclosure, after receiving the access request, the UPF sends a tunnel establishment request to the Layer 2 Tunneling Protocol Network Server (LNS) according to the LNS tunnel address with the username and password information requested from the SMF. After the terminal obtains the address, it accesses the user network.

[0079] Through Figure 1 The technical solution shown has problems such as poor security by configuring the public username and password information locally in the SMF, and the solution has a large granularity at the access point level and cannot effectively control a single user terminal by multiple means, resulting in low flexibility of user information. For users with multiple domain name requirements for a single terminal, it not only increases the risk of multi-domain name access for users but also increases the uncontrollability of users.

[0080] In the current 5G large-connection and multi-application scenarios, for the scenarios where user terminals need to access different networks without passwords, such as switching to different network services by simply modifying access point information, existing configuration schemes cannot effectively handle this situation.

[0081] In view of Figure 1 the deficiencies existing in the technical solutions, the present disclosure provides an access method for a communication network. The following will describe each step of the access method for the communication network in the exemplary embodiment in more detail with reference to the accompanying Figures 2 - 13 drawings and embodiments.

[0082] Figure 2 FIG. shows a flowchart of an access method for a communication network in an embodiment of the present disclosure. The method provided in the embodiment of the present disclosure can be executed by any electronic device with computing and processing capabilities. In the following illustrative examples, VPDN AAA is used as the execution entity for illustration.

[0083] As Figure 2 shown, an access method for a communication network is provided. The access method for the communication network includes:

[0084] In step S202, an authentication request sent by a session management function terminal is received.

[0085] In step S204, the access point information and international mobile subscriber identity information included in the authentication request are parsed.

[0086] In step S206, according to the access point information and the first correspondence between the pre-stored access point information and domain names, the corresponding domain name is determined.

[0087] In step S208, the corresponding user name information is determined according to the international mobile subscriber identity information.

[0088] In one embodiment, the user name information includes a user name and a password.

[0089] In step S210, the domain name and the user name information are bound to generate authentication information.

[0090] In one embodiment, the display form of the authentication information may include "user name @ domain name", and is not limited thereto.

[0091] In step S212, the authentication information is sent to the session management function terminal.

[0092] In one embodiment, the session management function terminal receives an authentication request sent by the session management function terminal, parses the authentication request to obtain the access point information and international mobile subscriber identification number information included in the authentication request, and then determines the corresponding domain name according to the access point information and the first correspondence between the pre-stored access point information and the domain name. At the same time, the corresponding user name information is determined according to the international mobile subscriber identification number information, and the authentication information generated by binding the domain name and the user name information is sent to the session management function terminal, realizing the service that the 5G wireless VPDN user terminal can be switched to different networks without configuration based on the SA architecture, and providing enterprises with a secure and convenient VPDN service and a flexible configuration experience in multiple scenarios. In addition, this solution is also applicable to the 4G LTE network deployed with AAA.

[0093] In summary, the above-mentioned method for accessing a communication network improves the security when accessing the communication network, enhances the user's access experience and access efficiency, reduces the configuration error rate when accessing the communication network, improves the user perception, and thus reduces the complaint traffic.

[0094] As Figure 3 shown, the method for accessing a communication network further includes:

[0095] In step S302, the first correspondence between the pre-stored access point information and the domain name is stored.

[0096] In one embodiment, an "APN - domain name" information library is set in the VPDN AAA, and in the "APN - domain name" information library, the first correspondence between the pre-stored access point information and the domain name is stored, ensuring the reliability of obtaining the domain name bound to the access point information.

[0097] In step S304, the second correspondence between the pre-stored international mobile subscriber identification number information and the user name information is stored.

[0098] In one embodiment, an "IMSI - user name" information library is set in the VPDN AAA, and in the "IMSI - user name" information library, the first correspondence between the IMSI information and the user name information is stored, ensuring the reliability of obtaining the user name information bound to the IMSI information.

[0099] As Figure 4 shown, determining the corresponding domain name according to the access point information and the first correspondence between the pre-stored access point information and the domain name includes:

[0100] In step S402, it is judged whether the access point information matches the pre-stored access point information.

[0101] In step S404, if it is determined that the access point information matches the pre-stored access point information, the domain name is determined according to the access point information and the first correspondence.

[0102] In one embodiment, it is determined whether the access point information matches the pre-stored access point information. If it is determined that the access point information matches the pre-stored access point information, the domain name is determined according to the access point information and the first corresponding relationship. The embodiments of the present disclosure improve the network access efficiency of 5G terminals.

[0103] As Figure 5 shown, determining the corresponding username information according to the International Mobile Subscriber Identity (IMSI) information includes:

[0104] In step S502, it is determined whether the IMSI information matches the pre-stored IMSI information.

[0105] In step S504, if it is determined that the IMSI information matches the pre-stored IMSI information, the username information is determined according to the IMSI information and the second corresponding relationship.

[0106] In one embodiment, it is determined whether the IMSI information matches the pre-stored IMSI information. If it is determined that the IMSI information matches the pre-stored IMSI information, the username information is determined according to the IMSI information and the second corresponding relationship. The embodiments of the present disclosure improve the network access efficiency of 5G terminals.

[0107] As Figure 6 shown, the network access method of the communication network further includes:

[0108] In step S602, if it is determined that the access point information does not match the pre-stored access point information, or it is determined that the IMSI information does not match the pre-stored IMSI information, an authentication failure message is fed back to the Session Management Function (SMF) terminal for the SMF terminal to generate an authentication request according to the locally configured public username information.

[0109] In one embodiment, by feeding back an authentication failure message to the SMF terminal when it is determined that the access point information does not match the pre-stored access point information, or it is determined that the IMSI information does not match the pre-stored IMSI information, for the SMF terminal to generate an authentication request according to the locally configured public username information, not only improves the operational reliability of the 5G terminal accessing the network, but also enhances the stability of the communication network, improves the usage perception of enterprise users, and thus reduces the user complaint traffic.

[0110] In one embodiment, in the solution where the session management function terminal generates an authentication request based on the publicly configured username information locally, if the user has preset the publicly configured username and password locally, the session management function terminal can generate an authentication request based on the publicly configured username information locally, realizing the function of the user accessing the network and ensuring the operational reliability of accessing the network.

[0111] In addition, those skilled in the art can understand that the user can judge whether to preset the above-mentioned publicly configured username and password according to actual needs. If the user does not preset the publicly configured username and password locally, then VPDN AAA feedbacks authentication failure information to the SMF. After receiving the authentication failure information, the SMF will judge that the access request of the UE is illegal and reject the access request of the UE, reducing the risk of information leakage after accessing the network and improving network security.

[0112] As Figure 7 shown, another method for a communication network to access the network is provided. In the following illustrative example, the session management function terminal is used as the execution entity for illustration. The method for a communication network to access the network includes:

[0113] In step S702, an authentication request is sent to the network access authentication device, and the network access authentication device can generate authentication information through the method for a communication network to access the network of any of the above technical solutions.

[0114] In step S704, the authentication information feedback by the network access authentication device is received, and the authentication information includes username information, domain name, and tunnel address information.

[0115] In step S706, the authentication information is sent to the user port function terminal for the user port function terminal to request the Layer 2 tunneling protocol network server for secondary authentication according to the tunnel address information.

[0116] In one embodiment, the session management function terminal sends an authentication request to the network access authentication device. First, the network access authentication device can generate authentication information through the method for a communication network to access the network in any of the above technical solutions. Second, the session management function terminal receives the authentication information feedback by the network access authentication device, and the authentication information includes username information, domain name, and tunnel address information. Then, the session management function terminal sends the authentication information to the user port function terminal for the user port function terminal to request the Layer 2 tunneling protocol network server for secondary authentication according to the tunnel address information, strengthening the network access security of the 5G terminal and improving the reliability of the 5G terminal accessing the network.

[0117] As Figure 8 shown, yet another method for a communication network to access the network is provided. In the following illustrative example, the user port function terminal is used as the execution entity for illustration. The method for a communication network to access the network includes:

[0118] In step S802, authentication information sent by the session management function terminal is received. The authentication information is generated by the network access method of the communication network capable of adopting any one of the above technical solutions, and the authentication information includes tunnel address information.

[0119] In step S804, a secondary authentication is requested from the Layer 2 Tunneling Protocol network server according to the tunnel address information.

[0120] In one embodiment, the user port function terminal receives the authentication information sent by the session management function terminal. The authentication information includes tunnel address information and tunnel password information, and a secondary authentication is requested from the Layer 2 Tunneling Protocol network server according to the tunnel address information and the tunnel password information, ensuring the network access security of the user accessing the network.

[0121] In one embodiment, taking the L2TP as the Layer 2 Tunneling Protocol network server as an example, the process of establishing an L2TP communication tunnel by the L2TP according to the tunnel address information and the tunnel password information is as follows:

[0122] (1) Establish a control connection of an L2TP communication tunnel.

[0123] (2) Trigger the establishment of an L2TP session according to the request of the inflow or outflow call.

[0124] In one embodiment, the LAC (L2TP Access Concentrator, Layer 2 Tunneling Protocol network server access concentrator) is one of the tunnel endpoints of the L2TP. The LAC and the LNS are peer nodes of the L2TP communication tunnel, and the L2TP communication tunnel is established between the LAC and the LNS and jointly maintained by the LAC and the LNS. Among them, the above L2TP communication tunnel includes at least one control connection and at least one L2TP session.

[0125] In one embodiment, multiple L2TP communication tunnels can be established between a pair of LAC and LNS. The multiple can be two or more, and the present disclosure does not make any limitation thereto.

[0126] As Figure 9 shown, requesting a secondary authentication from the Layer 2 Tunneling Protocol network server according to the tunnel address information, the network access method of the communication network further includes:

[0127] In step S902, the corresponding Layer 2 Tunneling Protocol network server is determined according to the tunnel address information.

[0128] In step S904, the tunnel address information request is sent to the Layer 2 Tunneling Protocol network server for the Layer 2 Tunneling Protocol network server to perform a secondary authentication.

[0129] In step S906, confirmation information for establishing a tunnel from the Layer 2 tunneling protocol network server is received. The confirmation information includes an IP address access domain name.

[0130] In step S908, the IP address access domain name is sent to the terminal for the terminal to access the network based on the IP address access domain name.

[0131] In one embodiment, the user port function terminal determines the corresponding Layer 2 tunneling protocol network server according to the tunnel address information, and sends a tunnel address information request to the Layer 2 tunneling protocol network server for the Layer 2 tunneling protocol network server to perform secondary authentication. After the Layer 2 tunneling protocol network server completes the secondary authentication, it sends confirmation information to the user port function terminal. The confirmation information includes an IP address access domain name. The user port function terminal receives the confirmation information for establishing the tunnel from the Layer 2 tunneling protocol network server, and sends the IP address access domain name to the terminal for the terminal to access the network based on the IP address access domain name. The embodiments of the present disclosure ensure the reliability of accessing the communication network and improve the security of accessing the communication network.

[0132] As Figure 10 shown, a method for accessing a communication network is provided. The above method can be implemented between a UE, an AMF, a UDM, an SMF, a VPDN AAA, a UPF, and an LNS. The method for accessing the communication network includes:

[0133] In step S1002, an access request is sent.

[0134] In one embodiment, a SIM card is installed in the UE, and APN information is set in the UE. When the user sends an access request through the UE, the access request includes IMSI information provided by the SIM card and the set APN information.

[0135] In step S1004, an authentication request is sent: The AMF receives the access request sent by the UE, and sends an authentication request to the UDM according to the access request. The authentication request includes IMSI information and APN information.

[0136] In step S1006, authentication information is returned: After receiving the authentication request sent by the AMF, the UDM authenticates the APN information in the authentication request.

[0137] In one embodiment, taking the home subscriber server as the UDM as an example, subscription information is pre-stored in the home subscriber server. After the home subscriber server receives the authentication request sent by the AMF, it uses the subscription information to check the APN information in the authentication request. If it is determined that the subscription information and the APN information are successfully verified, authentication information is generated based on the result of the successful verification of the subscription information and the APN information. The authentication information includes IMSI information and APN information, and the authentication information is returned to the AMF.

[0138] In one embodiment, taking the home subscriber server as the UDM as an example, subscription information is pre-stored in the home subscriber server. After the home subscriber server receives the authentication request sent by the AMF, it uses the subscription information to check the APN information in the authentication request. If it is determined that the subscription information and the APN information are not successfully verified, authentication failure information is fed back to the AMF so that the AMF can return access failure information to the user.

[0139] In step S1008, send a connection request: After the AMF receives the authentication information returned by the UDM, it sends a connection request to the SMF. The connection request includes IMSI information and APN information.

[0140] In step S1010, send an authentication request: After the SMF receives the connection request sent by the AMF, it sends an authentication request to the VPDN AAA so that the VPDN AAA can authenticate the IMSI information and the APN information.

[0141] In step S1012, obtain the domain name.

[0142] In one embodiment, after the VPDN AAA parses the authentication request, it obtains the APN information in the authentication request. The binding relationship between the APN information and the domain name is pre-stored in the VPDN AAA. When the APN information in the authentication request matches the pre-stored APN information, the domain name is obtained according to the binding relationship between the APN information and the domain name.

[0143] In one embodiment, the VPDN AAA parses the authentication request to obtain the APN information in the authentication request. The binding relationship between the APN information and the domain name is pre-stored in the VPDN AAA. When the APN information in the authentication request does not match the pre-stored APN information, authentication failure information is fed back to the SMF for the SMF to generate an authentication request based on the public user name information configured locally.

[0144] In step S1014, obtain the user name information.

[0145] In one embodiment, the VPDN AAA parses the authentication request to obtain the IMSI information in the authentication request. The binding relationship between the IMSI information and the user name information is pre-stored in the VPDN AAA. When the IMSI information in the authentication request matches the pre-stored IMSI information, the user name information is obtained according to the binding relationship between the IMSI information and the user name information.

[0146] In one embodiment, the VPDN AAA parses the authentication request to obtain the APN information in the authentication request. The binding relationship between the IMSI information and the user name information is pre-stored in the VPDN AAA. When the IMSI information in the authentication request does not match the pre-stored IMSI information, the VPDN AAA feeds back the authentication failure information to the SMF for the SMF to generate an authentication request according to the public user name information configured locally.

[0147] In step S1016, the authentication information is returned: the VPDN AAA parses the IMSI information and the APN information in the authentication request, obtains the domain name according to the binding relationship between the pre-stored APN information and the domain name, and obtains the user name information according to the binding relationship between the pre-stored IMSI information and the user name information. Subsequently, the VPDN AAA generates authentication information based on the user name information and the domain name information and returns an authentication message to the SMF.

[0148] In step S1018, a tunnel connection request is sent: the SMF receives the authentication message and sends a tunnel connection request to the UPF.

[0149] In step S1020, a tunnel establishment request is sent: after receiving the tunnel connection request, the UPF sends a tunnel establishment request to the LNS so that the LNS establishes a communication tunnel.

[0150] In step S1022, a tunnel establishment confirmation request is returned: the LNS establishes a communication tunnel according to the tunnel establishment request and returns a tunnel establishment confirmation request to the UE. The tunnel establishment confirmation request includes the IP address access domain name assigned to the UE.

[0151] In step S1024, access the network: the UE receives the tunnel establishment confirmation request and accesses the network according to the assigned IP address access domain name.

[0152] The technical solution proposed in the embodiments of the present disclosure is applicable to various network architectures, such as, for example, 3G or 4G or 5G, etc., but not limited thereto.

[0153] The technical solution proposed in the embodiments of the present disclosure solves the problem of high risk when using a public user name and password to supplement default information. Without adding network devices, the access efficiency of the communication network is improved, and the access security of the communication network is improved.

[0154] Such as Figure 11As shown, a method for accessing a communication network includes:

[0155] In step S1102, a determination is made as to whether the access point information is bound to a domain name. If so, the process proceeds to step S1104. If not, the process proceeds to step S1112. 5G wireless VPDN users only need to set access point information, such as APN1, on their terminals. The terminal initiates an access request to the AMF and verifies the request against the subscription information stored in the UDM.

[0156] If the verification is successful, the AMF sends a data connection request to the SMF. After receiving the request, the SMF initiates an authentication request to the VPDNAAA, which carries the APN1 information requested by the terminal and the user's IMSI information. If the verification fails, the AMF returns an access rejection message to the SMF.

[0157] In step S1104, the domain name bound to the access point information is obtained. An online database of APN and domain name bindings is added to the VPDN AAA. After receiving an authentication request, the VPDN AAA first identifies the APN1 information and queries the online database of APN and domain name bindings to obtain the corresponding APN and domain name bindings, thereby obtaining the domain name 1 information. If the domain name 1 information is not found, an access denial message is returned. If the domain name 1 information is found, the domain name bound to the access point information is obtained.

[0158] In step S1106, a determination is made as to whether the IMSI is bound to the domain name. If so, the process proceeds to S1108. If not, the process proceeds to S1112. The VPDN AAA identifies the IMSI information carried by the terminal and performs a binding check on the obtained domain name and IMSI information. If the check fails, the VPDN AAA returns an access rejection message to the SMF. If the check passes, the VPDN AAA queries the IMSI information and account binding information database to obtain the corresponding IMSI-account binding relationship and retrieve the account information.

[0159] In step S1108, the account information bound to the IMSI is obtained.

[0160] In step S1110, the account information and domain name are assembled and sent to the UPF. The VPDN AAA authorizes the username information using the username@domain1 format and sends the authorized username information to the SMF. It also returns an authentication message to the SMF, along with the username and password information. The return message includes the tunnel address information. Upon receiving this information, the SMF initiates a connection request to the UPF and sends the information in the return message to the UPF. The UPF initiates a secondary authentication request to the Layer 2 Tunneling Protocol network server based on the tunnel address information. After the tunnel is established, the terminal obtains the IP address and accesses the domain name network, enabling registration of different user information. This enables a 5G wireless VPDN user to access multiple domain names using a single account.

[0161] In step S1112, reject access information is returned.

[0162] In one embodiment, the AMF returns reject access information to the SMF so that the SMF can complete the username information according to the locally configured public username information, obtain the domain name information through the public username information, and send an authentication request to the VPDN AAA to complete the authentication process.

[0163] In step S1114, password-free verification is configured.

[0164] In one embodiment, the VPDN AAA can configure password-free verification when authorizing the username information. If password-free verification is configured, the username and password are not sent down.

[0165] In the embodiments of the present disclosure, the APN2 information may be one or more, and multiple may be two or more. The present disclosure does not limit this.

[0166] In one embodiment, if the terminal needs to switch to another network, it only needs to modify the access point information to the APN2 information in the terminal. The VPDN AAA receives the access request and returns the account@domain name 2 information, and initiates a tunnel authentication request to the LNS2, where the LNS2 is the tunnel server corresponding to the domain name 2.

[0167] In one embodiment, it is not necessary to modify the current one-time authentication process of the 5G wireless VPDN service, but it is necessary to upgrade and transform the AAA device. When the AAA receives an access request, through an internal trigger mechanism, it queries the user access point information matching rule, realizes automatically matching the domain name information for the user, queries the account information, and automatically assembles the username information composed of the domain name information and the account information into the form of account@domain name and sends it down.

[0168] The technical solution of the above embodiment proposes a method, device and system for 5G wireless VPDN user access without configuration based on the SA architecture, which can prevent 5G wireless VPDN users from being unable to access the enterprise domain name network due to the inability to configure the terminal or carry the user name and password, and realize the function of the terminal accessing different networks in the manner of using a single account for multiple domain names without configuration through an effective mechanism. This method modifies the original internal authentication method. After the user initiates an access request, VPDN AAA first queries the access point and domain name binding information library to match the corresponding domain name information, then verifies the binding relationship between the domain name and IMSI. After the verification passes, the account information is queried according to the IMSI information. The user name information assembled by the account @ domain name is issued in the VPDN AAA authorization information. According to the corresponding access information issued, UPF sends a tunnel establishment request to LNS. After the tunnel is successfully established, the terminal obtains an IP address and accesses the enterprise domain name network, and only needs to modify different access point information to realize registration of different domain name networks.

[0169] The following takes the implementation of VPDN AAA to realize user automatic identification of access point information matching and account @ domain name issuance as an example, and the specific code implementation process is as follows:

[0170] RADIUS Protocal

[0171] Code:Access-Aceept(2)

[0172] Packet identifier:0*1(1)

[0173] Length:107

[0174] Athenticator:13d1ccf980076a3d39d6a5a7d6996565

[0175] [This is a response to a request in frame 9]

[0176] [Time from request:0.007271000 seconds]

[0177] Attribute Value Pairs

[0178] AVP:t=Tunnel-Type(64)=6 Tag=0*00 val=L2TP(3)

[0179] AVP:t=Tunnel-Medium-Type(65)l=6 Tag=0*00 val=IP(1)

[0180] AVP: t = Tunnel-Server-Endpoint(67) l = 14 Tag = 0*00 val = 10.232.89.9

[0181] AVP: t = Tunnel-Password(69) l = 21 Tag = 0*00 val = Encrypted

[0182] AVP: t = Tunnel-Client-Auth-Id(90) l = 9 Tag = 0*00 val = 5gvpdn

[0183] AVP: t = Tunnel-Private-Group-Id(81) l = 9 Tag = 0*00 val = 5gvpdn

[0184] AVP: t = User-Name(1) l = 22 val = noc@noctest5.vpdn.js

[0185] The above embodiments of the present disclosure provide a method and system for 5G wireless VPDN user access without configuration based on the SA architecture, without modifying the 5G wireless VPDN user authentication process, only adding user access point information, domain name online information library and automatic query matching mechanism in AAA, and assembling the account @ domain name in the AAA authorization information as the user name to be sent down, so as to realize the access of 5G wireless VPDN users with a single account to multiple domain names, that is, realize the configuration-free authentication of a single account to multiple domain names. At the same time, it is possible to flexibly configure whether to skip password verification according to needs.

[0186] As Figure 12 shown, an access device 1200 for a communication network is provided. The access device for the communication network includes:

[0187] A receiving module 1202, configured to receive an authentication request sent by a session management function terminal.

[0188] A parsing module 1204, configured to parse the access point information and international mobile subscriber identification code information included in the authentication request.

[0189] A determining module 1206, configured to determine a corresponding domain name according to the access point information and a first correspondence between the pre-stored access point information and the domain name.

[0190] The determining module 1206 is further configured to determine corresponding user name information according to the international mobile subscriber identification code information.

[0191] A binding module 1208, configured to bind the domain name and the user name information and generate authentication information.

[0192] A sending module 1210, configured to send authentication information to a session management function terminal.

[0193] The following will refer to Figure 13 to describe the electronic device 1300 according to this embodiment of the present invention. Figure 13 The illustrated electronic device 1300 is merely an example and should not impose any limitation on the functions and usage scope of the embodiments of the present invention.

[0194] As Figure 13 shown, the electronic device 1300 is presented in the form of a general-purpose computing device. The components of the electronic device 1300 may include, but are not limited to: the at least one processing unit 1310 described above, the at least one storage unit 1313 described above, and a bus 1330 connecting different system components (including the storage unit 1313 and the processing unit 1310).

[0195] Among them, the storage unit stores program codes, and the program codes can be executed by the processing unit 1310, so that the processing unit 1310 executes the steps according to various exemplary embodiments of the present invention described in the above "Exemplary Method" section of this specification. For example, the processing unit 1310 can execute Figures 2 to 11 any of the steps shown in. The storage unit 1313 may include a readable medium in the form of a volatile storage unit, such as a random access storage unit (RAM) 13131 and / or a cache storage unit 13132, and may further include a read-only storage unit (ROM) 13133.

[0196] The storage unit 1313 may further include a program / utility 13134 having a set (at least one) of program modules 13135. Such program modules 13135 include, but are not limited to: an operating system, one or more application programs, other program modules, and program data. Each or some combination of these examples may include the implementation of a network environment.

[0197] The bus 1330 may represent one or more of several types of bus structures, including a storage unit bus or a storage unit controller, a peripheral bus, a graphics acceleration port, a processing unit, or a local bus using any bus structure in a variety of bus structures.

[0198] The electronic device 1300 can also communicate with one or more external devices 1400 (such as a keyboard, a pointing device, a Bluetooth device, etc.), and can also communicate with one or more devices that enable a user to interact with the electronic device 1300, and / or communicate with any device that enables the electronic device 1300 to communicate with one or more other computing devices (such as a router, a modem, etc.). Such communication can be carried out through the input / output (I / O) interface 1350. Moreover, the electronic device 1300 can also communicate with one or more networks (such as a local area network (LAN), a wide area network (WAN), and / or a public network, such as the Internet) through the network adapter 1360. As shown in the figure, the network adapter 1360 communicates with other modules of the electronic device 1300 through the bus 1330. It should be understood that although not shown in the figure, other hardware and / or software modules can be used in combination with the electronic device 1300, including but not limited to: microcode, device drivers, redundant processing units, external disk drive arrays, RAID systems, tape drives, and data backup storage systems, etc.

[0199] In an exemplary embodiment of the present disclosure, there is also provided a computer-readable storage medium, on which a program product capable of implementing the above method of this specification is stored. In some possible implementation manners, various aspects of the present invention can also be implemented in the form of a program product, which includes program code. When the program product runs on a terminal device, the program code is used to cause the terminal device to execute the steps according to various exemplary embodiments of the present invention described in the above "Exemplary Method" section of this specification.

[0200] In an exemplary embodiment of the present disclosure, there is also provided a program product for implementing the above method. It can adopt a portable compact disc read-only memory (CD-ROM) and include program code, and can run on a terminal device, such as a personal computer. However, the program product of the present invention is not limited thereto. In this document, the readable storage medium can be any tangible medium that contains or stores a program, and this program can be used by or in combination with an instruction execution system, apparatus, or device.

[0201] The program product may employ any combination of one or more readable media. The readable media may be a readable signal medium or a readable storage medium. The readable storage medium may be, for example, but not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination of the foregoing. More specific examples (a non-exhaustive list) of the readable storage medium include: an electrical connection having one or more wires, a portable disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disc read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing.

[0202] The computer readable signal medium may include a data signal propagated in a baseband or as part of a carrier wave, which carries the readable program code. Such a propagated data signal may take various forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination of the foregoing. The readable signal medium may also be any readable medium other than the readable storage medium, which can send, propagate, or transmit a program for use by or in connection with an instruction execution system, apparatus, or device.

[0203] The program code contained on the readable medium may be transmitted using any appropriate medium, including but not limited to wireless, wired, optical fiber cable, RF, etc., or any suitable combination of the foregoing.

[0204] The program code for performing the operations of the present invention may be written in any combination of one or more programming languages, including object-oriented programming languages such as Java, C++, etc., and also including conventional procedural programming languages such as the "C" language or similar programming languages. The program code may be executed entirely on the user's computing device, partially on the user's device, executed as a stand-alone software package, partially on the user's computing device and partially on a remote computing device, or entirely on the remote computing device or server. In the case of a remote computing device, the remote computing device may be connected to the user's computing device through any type of network, including a local area network (LAN) or a wide area network (WAN), or may be connected to an external computing device (e.g., by using an Internet service provider to connect through the Internet).

[0205] It should be noted that although several modules or units for performing actions are mentioned in the above detailed description, such a division is not mandatory. In fact, according to the embodiments of the present disclosure, the features and functions of the two or more modules or units described above may be embodied in one module or unit. Conversely, the features and functions of one module or unit described above may be further divided and embodied by a plurality of modules or units.

[0206] In addition, although the various steps of the methods in the present disclosure are described in a specific order in the accompanying drawings, this does not require or imply that these steps must be performed in that specific order, or that all of the shown steps must be performed to achieve the desired result. Additionally or alternatively, certain steps may be omitted, multiple steps may be combined into one step for execution, and / or one step may be decomposed into multiple steps for execution, etc.

[0207] From the description of the above embodiments, those skilled in the art can easily understand that the exemplary embodiments described herein can be implemented by software, or by a combination of software and necessary hardware. Therefore, the technical solutions according to the embodiments of the present disclosure can be embodied in the form of a software product, which can be stored in a non-volatile storage medium (which can be a CD-ROM, USB flash drive, mobile hard disk, etc.) or on a network, and includes several instructions to enable a computing device (which can be a personal computer, server, mobile terminal, or network device, etc.) to execute the methods according to the embodiments of the present disclosure.

[0208] After considering the specification and practicing the invention disclosed herein, those skilled in the art will readily conceive of other embodiments of the present disclosure. This application is intended to cover any variations, uses, or adaptations of the present disclosure, which follow the general principles of the present disclosure and include known common knowledge or conventional technical means in the technical field not disclosed in the present disclosure. The specification and examples are only to be considered as exemplary, and the true scope and spirit of the present disclosure are pointed out by the appended claims.

Claims

1. A method for accessing a communication network, characterized in that, Applied to an authentication, authorization, and accounting (AAA) server, including: Receiving an authentication request sent by a session management function terminal; Parsing the access point information and international mobile subscriber identity (IMSI) information included in the authentication request; Determining a corresponding domain name according to the access point information and a first correspondence relationship between the pre-stored access point information and the domain name, where the domain name represents the domain name of a virtual private dial-up network (VPDN); Determining corresponding user name information according to the IMSI information and a second correspondence relationship between the IMSI information and the user name information; Binding the domain name and the user name information and generating authentication information; Sending the authentication information to the session management function terminal.

2. The method for accessing a communication network according to claim 1, characterized in that, Further including: Pre-storing the first correspondence relationship between the access point information and the domain name; Pre-storing the second correspondence relationship between the IMSI information and the user name information.

3. The network access method of the communication network according to claim 2, wherein Determining the corresponding domain name according to the access point information and the first correspondence relationship between the pre-stored access point information and the domain name includes: Judging whether the access point information matches the pre-stored access point information; If it is determined that the access point information matches the pre-stored access point information, determining the domain name according to the access point information and the first correspondence relationship.

4. The method for accessing a communication network according to claim 2, characterized in that, Determining the corresponding user name information according to the IMSI information includes: Judging whether the IMSI information matches the pre-stored IMSI information; If it is determined that the IMSI information matches the pre-stored IMSI information, determining the user name information according to the IMSI information and the second correspondence relationship.

5. The method for accessing a communication network according to claim 3 or 4, characterized in that Further including: If it is determined that the access point information does not match the pre-stored access point information, or it is determined that the IMSI information does not match the pre-stored IMSI information, feedbacking authentication failure information to the session management function terminal for the session management function terminal to generate an authentication request according to the public user name information configured locally.

6. A method for accessing a communication network, characterized in that Applied to a session management function terminal, including: Sending an authentication request to an access network authentication device, where the access network authentication device can generate authentication information through the access network method of the communication network according to any one of claims 1-5; Receiving the authentication information feedback by the access network authentication device, where the authentication information includes user name information, the domain name, and tunnel address information; Sending the authentication information to a user port function terminal for the user port function terminal to request a second-layer tunneling protocol network server for secondary authentication according to the tunnel address information.

7. A method for accessing a communication network, characterized in that Applied to a user port function terminal, including: Receiving the authentication information sent by the session management function terminal, where the authentication information is generated by the access network authentication device through the access network method of the communication network according to any one of claims 1-5, and the authentication information includes tunnel address information; Requesting the second-layer tunneling protocol network server for secondary authentication according to the tunnel address information.

8. The method for accessing a communication network according to claim 7, wherein, Requesting the second-layer tunneling protocol network server for secondary authentication according to the tunnel address information includes: Determine the corresponding Layer 2 tunneling protocol network server according to the tunnel address information; Send the tunnel address information request to the Layer 2 tunneling protocol network server for secondary authentication by the Layer 2 tunneling protocol network server; Receive the confirmation information for establishing a tunnel from the Layer 2 tunneling protocol network server, where the confirmation information includes an IP address access domain name; Send the IP address access domain name to the terminal for the terminal to access the network according to the IP address access domain name.

9. An access device for a communication network, characterized in that, Applied to an authentication, authorization, and accounting (AAA) server, including: A receiving module for receiving an authentication request sent by a session management function terminal; A parsing module for parsing the access point information and international mobile subscriber identity (IMSI) information included in the authentication request; A determination module for determining a corresponding domain name according to the access point information and a first correspondence between the pre-stored access point information and the domain name, where the domain name represents the domain name of a virtual private dial-up network (VPDN); The determination module is further configured to determine corresponding user name information according to the IMSI information and a second correspondence between the pre-stored IMSI information and the user name information; A binding module for binding the domain name and the user name information and generating authentication information; A sending module for sending the authentication information to the session management function terminal.

10. An electronic device, characterized in that, Including: A processor; And A memory for storing executable instructions of the processor; Wherein, the processor is configured to execute the network access method of the communication network according to any one of claims 1 to 8 by executing the executable instructions.

11. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by the processor, it implements the network access method of the communication network according to any one of claims 1 to 8.

Citation Information

Patent Citations

  • Configuration-free wireless VPDN access method and system of terminal

    CN108235315A

  • Tunnel negotiation establishing method and device

    CN111182657A

  • Method and device for wireless LAN access authentication

    WO2013083026A1